Files
app-catalog-felhom.eu/templates/kimai/steps/def18c0c25cf49f7.yml
T
admin d75d1fd524
gates / gates (push) Successful in 3s
kimai: apache-2.57.0 -> 2.67.0 (within major 2), both venues proven (R-462, Part F)
The ONLY image move in this commit. Upstream stopped the `apache-` tag prefix after 2.57.0;
MEASURED 2026-09-30 on Docker Hub: `2.67.0`, `2`, `stable` and `apache` all resolve to ONE digest
(sha256:3084f1e5…), while `fpm`/`latest` are another — so the plain tag IS the Apache variant.
Written by upgrade-test.py --write-ladder:
- bench LXC 9401 (harness v4, box fixture Kimai via boxport): the seeded user read back before
  and after, Doctrine migrations ran (to Version20260804090000), 10-minute memory watch: kimai
  anon 6.0 % (cgroup 91.7 % = file cache, decision 22), kimai-db anon 45.0 %, 0 kills, 0 restarts;
  the abort starts and serves the data;
- box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 82.1 s, the
  seeded user read back through the app's own CLI.
The superseded step keeps its definition at steps/def18c0c25cf49f7.{yml,felhom.yml}.
Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/kimai/

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 13:27:45 +02:00

86 lines
2.5 KiB
YAML

# Kimai - Időkövetés és projektmenedzsment
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: mariadb
# RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
# ADMIN_EMAIL - Admin email
# ADMIN_PASSWORD - Admin jelszó (auto-generated)
services:
kimai:
image: kimai/kimai2:apache-2.57.0
container_name: kimai
restart: unless-stopped
depends_on:
kimai-db:
condition: service_healthy
environment:
- TZ=Europe/Budapest
- DATABASE_URL=mysql://kimai:${DB_PASSWORD}@kimai-db:3306/kimai?charset=utf8mb4&serverVersion=11.6.2-MariaDB
- ADMINMAIL=${ADMIN_EMAIL:-admin@example.com}
- ADMINPASS=${ADMIN_PASSWORD}
volumes:
- kimai_var:/opt/kimai/var
networks:
- traefik-public
- kimai-internal
deploy:
resources:
limits:
memory: 384M
healthcheck:
test: ["CMD", "curl", "-f", "http://127.0.0.1:8001"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.kimai.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.kimai.entrypoints=websecure"
- "traefik.http.routers.kimai.tls=true"
- "traefik.http.routers.kimai.tls.certresolver=letsencrypt"
- "traefik.http.services.kimai.loadbalancer.server.port=8001"
kimai-db:
image: mariadb:11.8
container_name: kimai-db
restart: unless-stopped
environment:
- MYSQL_ROOT_PASSWORD=${DB_PASSWORD}
- MYSQL_DATABASE=kimai
- MYSQL_USER=kimai
- MYSQL_PASSWORD=${DB_PASSWORD}
- TZ=Europe/Budapest
# MARIADB_AUTO_UPGRADE: on a MAJOR engine move the engine converts its own datadir (~7 s on a
# small DB, backs its system tables up first). Operator ruling 2026-09-13 on
# felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md. Inert until a
# major moves — and none may, until Slice 4 (R-448) ships: see CLAUDE.md, engine-major rule.
- MARIADB_AUTO_UPGRADE=1
volumes:
- kimai_db_data:/var/lib/mysql
networks:
- kimai-internal
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
volumes:
kimai_db_data:
kimai_var:
networks:
traefik-public:
external: true
kimai-internal: